Executive brief
GFI Archiver, a solution used for archiving corporate emails and files, contains a security flaw in its IMAP server configuration settings. An authenticated attacker can inject malicious scripts into the configuration page, which will then execute in the browsers of other administrators or users who view that page. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in GFI Archiver versions prior to 15.13. The flaw is located in the /Archiver/ImapServerWizard.aspx component, specifically within the server URL parameter. The application's SaveAllConfigSettings() function fails to perform proper output encoding before storing the input. An authenticated attacker with access to the IMAP Server configuration can inject a malicious payload that executes in the context of any user who subsequently views the configuration page. This can be used to hijack sessions or perform unauthorized administrative actions. The issue is resolved in version 15.13.
Affected products
- GFI Software Archiver before 15.13
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory